Stored XSS Vulnerability in Articles Anywhere Extension for Joomla by Regular Labs
CVE-2026-85195
7.5HIGH
What is CVE-2026-85195?
The Articles Anywhere extension for Joomla is susceptible to a stored Cross-Site Scripting (XSS) vulnerability that arises from inadequate validation of user-supplied content. Specifically, the extension allows the inclusion of link options such as 'onclick' and 'onmouseover'. In versions prior to 20.0.0, these options are incorporated into the generated HTML without properly verifying the article author's trust level. This oversight permits malicious scripts to be executed, compromising the integrity of the web application and potentially leading to unauthorized access or data leakage.
Affected Version(s)
Articles Anywhere (Free, Pro) extension for Joomla 14.0.0-19.0.6
